Anonymous
2026-04-21 04:49:22
(4 months ago)
2026-04-21T06:49:04.457559+02:00 nimbus sshd[285021]: pam_unix(sshd:auth): authentication failure; l ...
show more
2026-04-21T06:49:04.457559+02:00 nimbus sshd[285021]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=172.70.240.167
2026-04-21T06:49:05.848279+02:00 nimbus sshd[285021]: Failed password for invalid user codex from 172.70.240.167 port 63902 ssh2
2026-04-21T06:49:21.244767+02:00 nimbus sshd[285041]: Invalid user test from 172.70.240.167 port 53792
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-04-13 15:54:42
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 11:54:37.565861 2026] [security2:error] [pid 2439318:tid 2439318] [client 172.70.240.167:14279] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mandavaassoc.com"] [uri "/.git/config"] [unique_id "ad0RvfIzI7DR4nnsPZwS6gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-04-13 07:24:44
(5 months ago)
172.70.240.167 - - [13/Apr/2026:
...
Brute-Force
๐บ๐ธ
wimaxnz
2026-04-12 06:58:29
(5 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-08 12:33:20
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 08:33:11.158995 2026] [security2:error] [pid 3173396:tid 3173396] [client 172.70.240.167:9365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cynosurehomeservices.com"] [uri "/.git/refs/heads/master"] [unique_id "adZLB6fpQZX9JNVdrCBMHQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-06 05:24:48
(5 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-193)
Hacking
๐ฒ๐พ
Rizzy
2026-04-05 12:29:49
(5 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 14:04:02
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 10:03:55.154303 2026] [security2:error] [pid 7786:tid 7786] [client 172.70.240.167:12154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.internationalavionics.com"] [uri "/.git/refs/heads/master"] [unique_id "adEaS6eh3GgGnX_BOiG0IAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 21:23:21
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 17:23:18.384489 2026] [security2:error] [pid 1168:tid 1168] [client 172.70.240.167:12646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "my1611.com"] [uri "/.git/index"] [unique_id "adAvxgd0wAY0X5U6eRXw9gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-03 20:53:57
(5 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 15:47:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 11:47:24.775730 2026] [security2:error] [pid 16245:tid 16245] [client 172.70.240.167:13791] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffreycopeland.com"] [uri "/.env.production"] [unique_id "ac_hDHicgMeKpTralEUxCgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 10:31:12
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 06:31:07.782169 2026] [security2:error] [pid 7910:tid 7925] [client 172.70.240.167:11792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tmsx2.com"] [uri "/.git/HEAD"] [unique_id "ac-W67CgcvqDIW-fygKhHAAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 03:25:03
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 23:24:55.063975 2026] [security2:error] [pid 27405:tid 27405] [client 172.70.240.167:12056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lozzy.net"] [uri "/.git/logs/HEAD"] [unique_id "ac8zB6wWklt2r4iKi_NlqQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
Markus Woegerbauer
2026-04-03 02:56:27
(5 months ago)
(mod_security) mod_security triggered on hostname [redacted] 172.70.240.167 (DE/Germany/-)
SQL Injection
Anonymous
2026-04-02 20:10:40
(5 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH